FFERMing Up Risk Culture at FIs
- Roy Urrico

- Jun 24
- 5 min read
By Roy Urrico

Federal banking agencies have intensified scrutiny around how financial institutions (FIs) manage risk, evaluate exposure, tighten underwriting, prevent fraud, as well as other risky behaviors and cultures. Banking expert Dr. Jeffrey L. Edwards sat down with Finopotamus for a deep discussion on how traditional risk frameworks at many FIs are no longer sufficient for today’s interconnected threat environment.

Edwards, founder and CEO of Charlotte, N.C.-based FFERM Technologies, an AI-powered enterprise risk-intelligence platform built for the financial services industry, believes credit unions and banks must move beyond isolated risk scoring and adopt a more dynamic approach. FFERM, which stands for four-factor enterprise risk management, developed a patent-pending methodology designed to expand beyond traditional likelihood-and-severity scoring.
The FFERM model evaluates risk through four elements:
Compounding: Whether a risk is systemic, growing or likely to amplify other risks.
Severity: Potential damage if the risk materializes.
Likelihood: Probability of the risk occurring.
Predictability: Whether leaders attained enough visibility to anticipate imminent risks.
“The four-factor model takes the conversation out of the math and puts it into behavior,” Edwards told Finopotamus. “If I have high compounding, I know the risk is systemic and growing. If I have high compounding and high severity, I know I have a severe risk that is systemic and growing. If predictability is low, I may not know when it is coming. That is the kind of conversation boards, CROs (chief risk officers), CCOs (chief compliance officers) and audit leaders should be having.”
Creating Four-Factor Risk Intelligence
While working as a consultant to evaluate complex risk frameworks across financial services organizations, Edwards identified critical flaws in traditional risk quantification methods. The catalyst was a specific realization: two risks with identical likelihood-impact scores could differ dramatically in actual business significance due to cascading effects, systemic interconnections, and predictability factors that traditional matrices completely ignored.
“The foundation of using ‘likelihood’ and ‘severity’ as the two variables or two factors used to identify risk and to quantify has not changed in 40 years,” he explained. The primary risk-based document Edwards referred to was the Fiscal Year 1984 Defense Budget that fundamentally introduced the military system safety standards.
That is the foundation as to why a lot of different incidents have happened over the years, Edwards emphasized. “That calculation really focuses on purely the impact and the likelihood that that event happens. But anything outside of that you do not have a viewpoint into.”
Edwards noted the two-variable emphasis (likelihood and severity) also does not provide insight into interconnected risks. “Like in credit unions or banks or any organization that fails due to economic pressures, liquidity issues or capital issues. They do not really realize that one issue can lead to another, which leads to a bank run or liquidity issue, and you are out of business. A lot of organizations understand it, but they have not had a framework to show it, verify it, and have a way to defend against it.”
Rather than accepting these limitations as inherent to risk management, Edwards developed the alternative FFERM framework that could capture risk complexity while remaining practical for enterprise deployment.
Looking at the existing likelihood and the severity factors, Edwards noted, “It is just you have not evolved it over the past years to see what else you can incorporate within that framework.” His research identified that in the past 20 or so years, the real risk centered around risk contagion or risk correlation. “If you look at it just from a likelihood and a severity perspective, you do not see the cascading events of risk. You do not have a way of calculating it. You do not have a way of modeling it,” said Edwards.
Framed to Prevent Black Swan Events
Beyond modelling, the cascading or compounding of “black swan” events emerged into the field. In cybersecurity, a black swan is an unpredictable, high-impact occurrence that challenges conventional expectations and is frequently rationalized in retrospection as foreseeable.
“You have an unpredictable event that causes a major outage or a major incident, a major financial impact. When you have that situation, it is hard to manage and put mitigation factors in place because you do not know when it is happening,” Edwards explained.
Many FIs, prompted by regulators, prepare for “that one day in 20 years, you're going to have a $20 million event that's going to basically take you out,” Edwards further explained. However, when he was looking at what is impacting the financial services market, he identified two areas as being the most influential: risk compounding and unpredictability.
FIs cannot necessarily predict 100% “what” is going to happen, but they can observe leading indicators that “something” is about to happen, Edwards noted. “If you're looking at those leading indicators, then you have a viewpoint into the likelihood that this black swan event will happen.”
“What made me put it into a framework is I decided to try to back test it to certain events that happened to see what were the indicators that something was going to be happening,” said Edwards. “The risk events that happened in the external markets gave us an indication that things were happening, but people weren't looking at the external markets as well as the internal activities going on in their organization.”
The black swan events Edwards reviewed include:
2008: the bankruptcy of Lehman Brothers, which was the climax of the subprime mortgage crisis.
2016: Wells Fargo’s systemic crisis when it was fined $185 million for the creation of about 1.5 million fake deposit accounts and 500,000 credit cards without customer consent.
2023: The collapse of Silicon Valley Bank (SVB), the second-largest bank failure in U.S. history.
“Wells Fargo was probably one of the ones that was the most esoteric in that it was not completely outwardly visible from an indicator perspective,” said Edwards. “What was visible was how culture was impacting how people operated and thereby doing things that may not have been consistent from a risk perspective.”
The FFERM Behavior Approach
The FFERM methodology also looks at and measures culture, Edwards said. “My platform is built on the four factors: the likelihood, severity, compounding and predictability. Everything is built upon that. I have taken that score, weighted in a way that you get a composite score (and) translated that score into a behavior.”
To obtain enough information to do an analysis of a financial service organization, FFERM provides a questionnaire, about five questions for each of the factors. Answers are usually provided by “the owner of the risk or the people who are closest to the risk, or the products that they're implementing, or processes they're implementing, that is causing the risk in the first place,” said Edwards.
FFERM then uses AI to develop its responses. “If you have the risk information, the verbiage of that risk, if you've described it in any way, my AI can identify the compounding likelihood of severity and predictability of that risk event,” Edwards said. The FFERM system uses about 150 AI/machine learning quantitative financial models within the whole implementation,” he explained.
FFERM can access any one of five intelligence engines including solutions for credit unions or banks, insurers, registered investment advisers (RIAs), and broker-dealers. The FFERM system can also provide governance, risk, and compliance (GRC) intelligence, and an AI risk advisor, which is an interactive chat based off of the FI’s system FFERM is monitoring.
Edwards conceptualized the FFERM methodology in 2024. The following year, 2025, was a notable year with the platform development phase (the first quarter), the proof of concept validated (second quarter), and FFERM Technologies founding (the fourth quarter), all taking place.



